# Modifying fields in every saved search, pipeline rule, dashboard, alert, and extractors

**URL:** <https://community.graylog.org/t/modifying-fields-in-every-saved-search-pipeline-rule-dashboard-alert-and-extractors/27703>\
**Category:** Graylog Central (peer support)\
**Created:** [February 13, 2023, 5:39pm UTC](https://community.graylog.org/t/modifying-fields-in-every-saved-search-pipeline-rule-dashboard-alert-and-extractors/27703 "2023-02-13T17:39:22Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mmurdock](https://avatars.discourse-cdn.com/v4/letter/m/b5ac83/32.png) [@mmurdock](https://community.graylog.org/u/mmurdock)\
**Post date:** [February 13, 2023, 5:39pm UTC](https://community.graylog.org/t/modifying-fields-in-every-saved-search-pipeline-rule-dashboard-alert-and-extractors/27703/1 "2023-02-13T17:39:22Z")

</div>

Hello,

I’m running Graylog 5.0.3 community edition. A recent upgrade to the sidecar agent has resulted in a field name change for all winlogbeat events. Instead of beginning with “winlogbeat\_” many of them now begin with “winlogbeat\_winlog\_”

I have not been able to identify a practical way to rename those events in winlogbeat, and I did not want to create a pipeline rule that individually renamed hundreds of fields.

At this point my thought is that if winlogbeat is moving to this new naming scheme, I might as well adopt it. So I would like to go through all of my saved searches, dashboards, alerts, pipeline rules, extractors, etc. and replace “winlogbeat\_” with “winlogbeat\_winlog” which should take care of just about every situation where I might experience a problem due to this naming change.

My question to the community is - is there anyway you can think of that might help me do this in a more automated way? Perhaps exporting a content pack with all relevant items and doing a text search/replace and then re-importing the content pack?

Thanks for any input.

---

<div class="post-metadata">

**Author:** ![H2Cyber](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/h2cyber/32/12536_2.png) [@H2Cyber](https://community.graylog.org/u/H2Cyber)\
**Post date:** [February 13, 2023, 8:42pm UTC](https://community.graylog.org/t/modifying-fields-in-every-saved-search-pipeline-rule-dashboard-alert-and-extractors/27703/2 "2023-02-13T20:42:48Z")

</div>

Please upvote the following feature request which would make the field management nightmare much easier once it gets emplemented (IF it ever gets implemented … ).

> <https://github.com/Graylog2/graylog2-server/issues/13479>
>
> In order to comply with the \[Graylog Information Model Schema\](https://schema.gr…aylog.org/en/stable/) (GIM), a lot of work needs to be done on existing setups in order to identify provenance and uses of existing fields, and rename them according to GIM. The purpose of this feature request is to make field management easier via the Graylog UI, by providing a visual indicator that shows where fields are being used across : 
> 
> \- Inputs
> \- Extractors
> \- Pipeline rules
> \- Streams
> 
> Similar to https://github.com/Graylog2/graylog2-server/pull/11474 but for fields
> 
> \## Your Environment
> \* Graylog Version: 4.3.7

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [February 13, 2023, 11:00pm UTC](https://community.graylog.org/t/modifying-fields-in-every-saved-search-pipeline-rule-dashboard-alert-and-extractors/27703/3 "2023-02-13T23:00:07Z")

</div>

Hey @mmurdock

Addingon to @H2Cyber suggestion.

If need be, you can disble the pre-fix , if that helps.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/4/4f9710563938f0eb92198d4e9f9c31f2345159b0.png)

---

<div class="post-metadata">

**Author:** ![mmurdock](https://avatars.discourse-cdn.com/v4/letter/m/b5ac83/32.png) [@mmurdock](https://community.graylog.org/u/mmurdock)\
**Post date:** [February 14, 2023, 9:42pm UTC](https://community.graylog.org/t/modifying-fields-in-every-saved-search-pipeline-rule-dashboard-alert-and-extractors/27703/4 "2023-02-14T21:42:00Z")

</div>

Thanks for the suggestion gsmith. I did try this, but unfortunately it just strips the winlogbeat\_ and winlogbeat\_winlog\_ prefix off the fields altogether. I have had to resort to a fairly manual method of starting at inputs/extractors and working my way through pipeline rules, alerts/notifications, saved searches, and dashboards. In some cases it’s simply a replacement of “winlogbeat\_” with “winlogbeat\_winlog\_”, but in other cases it’s an entirely different field name, such as “winlogbeat\_log\_name” to “winlogbeat\_winlog\_channel.” It’s tedious and I have chosen to purge index history, so overall a frustrating process but hopefully this is a situation that doesn’t come up very often.

---

<div class="post-metadata">

**Author:** ![mmurdock](https://avatars.discourse-cdn.com/v4/letter/m/b5ac83/32.png) [@mmurdock](https://community.graylog.org/u/mmurdock)\
**Post date:** [February 14, 2023, 10:14pm UTC](https://community.graylog.org/t/modifying-fields-in-every-saved-search-pipeline-rule-dashboard-alert-and-extractors/27703/5 "2023-02-14T22:14:49Z")

</div>

A feature that would have greatly helped with this process would be if we could choose to overwrite searches, extractors, rules, dashboards, etc. during Content Pack installation. I have been able to use Content Packs to make mass modifications of field names, but without the ability to overwrite I have to do a lot of manual deletion prior to installing it. I have created a feature request here:

[https://github.com/Graylog2/graylog2-server/issues/14672](https://github.com/Graylog2/graylog2-server/issues/14672)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [February 28, 2023, 10:15pm UTC](https://community.graylog.org/t/modifying-fields-in-every-saved-search-pipeline-rule-dashboard-alert-and-extractors/27703/6 "2023-02-28T22:15:35Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
